A person trades in the app with a DFNS passkey session. Programs use scoped API keys. Agent, market-making bot and test-client keys are all checked the same way on every request. They differ in who issues the key, not in the account and route authorization model. Each key is bound to one account. A trade scope includes read. A staging or production venue refuses a test-client key on every request, even if a copy of the key exists there. The published docs do not expose the server-only issuance endpoint. When a key is rotated, the old key keeps working for 5 more minutes, so requests already in flight still land. Then it expires.

When a key is refused

A refused request answers with the external-rest-error/v1 envelope. apiKeyRejection names the reason. Only a 503 is worth a retry; for every other refusal, fix the cause first. A key is a trading credential, not a signing credential. Protect it as carefully as an order entry credential. An expired or revoked key is refused on every request. The owner can revoke agent access from the app with a passkey. A bot follows its server-side rotation path. A key cannot list or revoke other keys. For agent approval, see Trading agents. For bot integration, see Market maker quickstart. For the shared route and scope rules, see Authentication models.